I suppose that even for a script kiddie it takes extra time and patience to come up with such a spoofed IRC channel getting crowded with infected hosts. Drawing courtesy of a script kiddie's wishful thinking. Here are some screenshots from the real world, and some of the most recent developments I covered in previous posts.
Monday, January 14, 2008
PAINTing a Botnet IRC Channel
I suppose that even for a script kiddie it takes extra time and patience to come up with such a spoofed IRC channel getting crowded with infected hosts. Drawing courtesy of a script kiddie's wishful thinking. Here are some screenshots from the real world, and some of the most recent developments I covered in previous posts.
The Pseudo "Real Players"
What happened with the recent RealPlayer massive embedded malware attack? Two of the main hosts are now, and the third one ucmal.com/0.js is strangely loading an iframe to ISC's blog in between the following 61.188.39.218/pingback.txt which was returning the following message during the last couple of hours "You're welcome for being saved from near infection".As I'm sure others too like to analyze post incident response behavior of the malicious parties, in respect to this particular attack, during the weekend they took advantage of what's now a patent of the Russian Business Network, namely to serve a fake 404 error message but continue the campaign. However, in RBN's case, only the indexes were serving the fake account suspended messages, but the campaign was still active on the rest of the internal pages. In the RealPlayer's campaign case, the 404 error messages themselves were embedded with the same IFRAMEs as well, in order to make it look like there's an error, at least in front of the eyes of the average Internet user.
Despite that the main campaign domains are blocked on a worldwide scale, the hundreds of thousands of sites that originally participated are still not clean and continue trying to load the now down domains. Moreover, the big picture has to do with a fourth domain as well, yl18.net/0.js, that used to be a part of the same type of massive malware embedded attack in November, 2007.
Why pseudo "real players" anyway? Because for this attack, they took advantage of what can be defined as a fad, namely the use seperate exploit as the cornerstone of the campaign, at least if its massive infection they wanted to achieve. The "real players" or script kiddies on the majority of occasions, serve exploits on a client-side matching basis, and therefore the more diverse the exploits set, the higher the probability a vulnerable application will be detected and exploited. Therefore, given the number of sites affected it could have been much worse than it is currently based on speculations of the success rate of the campaign in terms of infections, not the sites affected - a success by itself. Execution gone wrong given the foundation for the attack - until the next time.
Thursday, January 10, 2008
Malware Serving Exploits Embedded Sites as Usual
The combination of the recent RealPlayer exploit and MDAC is a fad, but the very same is getting embraced in the short-term by malicious parties in China that have also started combining the Internet Explorer VML Download and Execute Exploit (MS07-004), thanks to recent localized forum postings on modifying the third exploit. Let's assess several sample domains.8v8.biz/ms07004.htm (58.53.128.98) is such a domain that's serving a combination of these starting with Exploit-MS07-004 :
Result: 12/32 (37.5%)
File size: 3432 bytes
MD5: bafab9b8e38527e9830047fd66b39532
SHA1: b81abcf63a2c4bcf43526f28aec20fca2f58d67c
8v8.biz/1.htm - MDAC also loads 8v8.biz/06014.html in between 8v8.biz/r.htm - real player unobfuscated, wheere all of these attempt to load 8v8.biz/v.exe - Worm.Win32.AutoRun.bkx; Win32/Cekar!generic
Result: 27/31 (87.10%)
File size: 19501 bytes
MD5: 7b101f7baeae0ebab9ecc06fdb9542dc
SHA1: 36ffa50ce3873fb04c13c80421c205a7760f47ca
The binary is using a default set of known executables of anti malware products, and is installing a default debugger injected upon execution of any of these, and is therefore successfully killing many of the applications.
Another exploit serving domain with a very diverse set of exploits used, but again serving the faddish RealPlayer plus MDAC combination is uc147.com (218.107.216.85) :
uc147.com/test/MS07004.htm
uc147.com/test/PPs.htm
uc147.com/test/biaxing06014.Htm
uc147.com/test/index.htm
uc147.com/test/Click_here.html
uc147.com/test/PPLIVE.htm
uc147.com/test/Thunder.html
uc147.com/test/bf.htm
uc147.com/test/Open.htm
uc147.com/test/ms06014.htm
uc147.com/test/jetAudio%207.x.htm
where all are trying to load uc147.com/zy.exe :
Result: 24/32 (75%)
File size: 15456 bytes
MD5: 3a0804d8e12706e97cdda6aa4f50ef5f
SHA1: cfd2f158a658dc0d8618c35806b94008b4fb1c0f
The third domain is great example of what's an emerging trend rather than a fad, namely the use of comprehensive multiple IFRAMES loading campaigns. qx13.cn/3.htm (61.174.61.94) (IE COM CreateObject Code Execution (MS06-042) which loads sp.070808.net/23.htm, (75.126.3.218) where the following try to load as well :
sp.070808.net/in.htm
wc.070808.net/37.htm
az.sbb22.com/hh.htm
um.uuzzvv.com/uu.htm
fa.55189.net
acc.jqxx.org/40.htm
ktv.mm5208.com/25.htm
Two other IFRAMES within within qx13.cn/3.htm, w.aeaer.com/ae.htm (75.126.3.216) loads the same IFRAMES, and qi.ccbtv.net/btv.htm (66.90.79.138) again loads the same IFRAMEs. It gets even more complicated and the ecosystem more comprehensive as the secondary IFRAMEs logically load many others such as :
68yu.cn/s29.htm
ermei.loveyoushipin.com/pic/9041.htm
yun.yun878.com/web/6619038.htm
ppp.749571.com/ww/new82.htm
2.xks08.com/dm1.htm?60
ad.2365.us/110
The more complicated and dynamic these IFRAME-ing attacks get, the higher the campaign's lifecycle becomes, making it harder the determine where's the weakest link, and making it easier for the malicious parties to evaluate which node needs a boost by including new domains spread across different netblocks like this case.
Tuesday, January 08, 2008
The Invisible Blackhat SEO Campaign
Count this as a historical example of a blackhat SEO campaign, and despite that "Fresh Afield's" blog (blogs.mdc.mo.gov) is now clean, cached copies confirm the existence of hidden links that were embedded on each and every post on it, apparently due to a compromise. The blackhat SEO links invisible embedded within the blog's posts on the other hand point to a compromised account at the Texas A&M University (aero.tamu.edu/people/raktim), as you can see in the screenshot. Moreover, there's also a visible part of the campaign that was located under blogs.mdc.mo.gov/custom/?0f, and as usual, once the blackhat SEO pages were either uploaded or embedded like it happened in this case, the campaigns under the blogs.mdc.mo.gov URL were spammed across the Internet.
Monday, January 07, 2008
MySpace Phishers Now Targeting Facebook
The "campaigners" behind the MySpace phishing attack which I briefly assessed in previous posts seem to have started targeting Facebook as well. Ryan Singel comments, and quotes me in a related article :"Hackers for the first time are targeting the popular social networking site Facebook with a phishing scam that harvests users' login details and passwords. Some Facebook users checking their accounts Wednesday found odd postings of messages on their "wall" from one of their friends, saying: "lol i can't believe these pics got posted.... it's going to be BADDDD when her boyfriend sees these," followed by what looks like a genuine Facebook link. But the link leads to a fake Facebook login page hosted on a Chinese .cn domain. The fake page actually logs the victims into Facebook, but also keeps a copy of their user names and passwords."
Compared to their previous MySpace phishing campaign that was also serving malware in between, this was was purely done for stealing accounting data of Facebook users only. And as we're on a Facebook malicious campaigns topic, impersonating Facebook's login or web presence from a blackhat SEO perspective to serve malware is always trendy. Take this fake facebook login subdomain serving malware for instance - facebook-login.vylo.org (209.160.73.132) redirects to iscoolmovies.com/movie/black/0/2/541/1/ which attempts to load 209.160.73.132/download/502/541/1/ where 209.160.73.132/dw.php is the adware in this case - Adware:Win32/SmitFraud. And yet another one - facebook-login-61248sf1.krantik.info (89.149.206.225) whose once deobfuscated javascript attempts to load topsearch10.com/search.php (209.8.25.156). Spammy, yammy.
Massive RealPlayer Exploit Embedded Attack
This malware embedded attack is massive and ugly, what's most disturbing about it is the number of sites affected, which speaks for coordination at least in respect to having established the infrastructure for serving the exploit before the vulnerability became public :"One of our readers noted that there are a number of state government and educational sites that appear to have been compromised with the uc8010 domain. Upon review, I see that some of these have already been cleaned up. However, the .gov and .edu sites are only a few of the many many sites that are turned up via google searches for the uc8010 domain. As that domain was only registered as of Dec 28th, compromises of websites probably occurred in the past week."
According to SANS, there are only two domains involved in the attack uc8010.com/0.js and ucmal.com/0.js however, there's also a third one, namely rnmb.net/0.js. This attack is nothing else but "embedded malware as usual", javascript obfuscations, multiple IFRAME redirectors to and from internal pages, and scripts within the domains. Let's assess those that are still active :
- n.uc8010.com/0.js returns "ok ^_^" message and loads c.uc8010.com/ip/Cip.aspx (61.188.39.218) which says "Hello", furthermore, c.uc8010.com/0/w.js loads c.uc8010.com/1.htm; count38.51yes.com/click.aspx?id=389925362&logo=1 and s106.cnzz.com/stat.php?id=742266&web_id=742266
The internal structure is as follows :
c.uc8010.com/1.htm - attempts MDAC ActiveX code execution (CVE-2006-0003) in between the following
c.uc8010.com/046.htm - javascript obfuscation
c.uc8010.com/r.htm - real player exploit
c.uc8010.com/014.js - javascript obfuscation
c.uc8010.com/111.htm - unobfuscated real player exploit
- ucmal.com/0.js (122.224.146.246) - another obfuscation
- rnmb.net/0.js says "ok! ^_^ Don't hank me !" but compared to the first two that are still active, this one is down as of yesterday, despite that it still remains embedded on many sites
Detection rate for the unobfuscated exploit :
Result: 17/32 (53.13%) - Exploit-RealPlay; JS/RealPlay.B
File size: 3003 bytes
MD5: a85a28b686fc2deedb8d833feaacef16
SHA1: 0282e945ded85007b5f99ddee896ed5e31775715
Detection rate for the obfuscated exploit :
Result: 11/32 (34.38%) - JS/Agent.AMJ!exploit; Trojan-Downloader.JS.Agent.amj
File size: 2880 bytes
MD5: d363ffca061ebf564340c4ac899e3573
SHA1: 1226d3d9fcc5052a623b481b48443aeb246ab5db
A lot of university, and international government sites continue to be embedded with the script, and so is Computer Associates site according to this article :
"Part of security software vendor CA's Web site was hacked earlier this week and was redirecting visitors to a malicious Web site hosted in China. Although the problem now appears to have been corrected, cached versions of some pages in the press section of CA.com show that earlier this week the site had been redirecting visitors to the uc8010.com domain, which has been serving malicious software since late December, according to Marcus Sachs, director of the SANS Internet Storm Center."
Compared to each and every malware embedded attack that I assessed in 2007, including all of Storm Worm's campaigns, they were all relying on outdated vulnerabilities to achieve their success, but this one is taking advantage of the now old-fashioned window of opportunity courtesy of a malicious party enjoying the given the lack of a patch for the vulnerability. Why old-fashioned? Because malware exploitation kits like MPack, IcePack, WebAttacker, the Nuclear Malware Kit and Zunker, changed the threatscape by achieving a 100% success rate through first identifying the victim's browser, than serving the exact exploit. Another such one-vulnerability-serving malware embedded attack was the MDAC exploits farm spread across different networks I covered in a previous post. It's also interesting to note that a MDAC live exploit page was also found within what was originally thought to be a RealPlayer exploit serving campaign only. Shall we play the devil's advocate? The campaign would have been far more successful if a malware exploitation kit was used, as by using a single exploit only, the campaign's success entirely relies on the eventual presence of RealPlayer on the infected machine.
Subscribe to:
Posts (Atom)
Blog Archive
About Me
- Dancho Danchev
- Independent Security Consultancy, Threat Intelligence Analysis (OSINT/Cyber Counter Intelligence) and Competitive Intelligence research on demand. Insightful, unbiased, and client-tailored assessments, neatly communicated in the form of interactive reports - because anticipating the emerging threatscape is what shapes the big picture at the end of the day. Approach me at dancho.danchev@hush.com
Total Pageviews
Labels
- 29A (1)
- 29A Virus Coding Group (1)
- 419 Scam (4)
- AbdAllah (1)
- Abdallah Internet Hizmetleri (1)
- Able Danger (1)
- Abuse Department (1)
- Active Security Monitor (1)
- Advance Fee Scam (2)
- Advanced Persistent Threat (2)
- Advertising (3)
- Adware (3)
- Affiliate Network (7)
- Ahmad Al Agha (1)
- Al Qaeda (3)
- Aleksandr Zhukov (1)
- Allied Group Inc (1)
- Amazon AWS (1)
- ANA Spoofer Project (1)
- Android (2)
- Anonymity (31)
- Anonymizer (1)
- Anonymous (1)
- Anonymous Hacking Collective (1)
- Anti-Phishing Group (1)
- Antivirus (6)
- Antivirus Signatures (3)
- Anton Nikolaevich Korotchenko (1)
- AOL (2)
- API (1)
- Apple (1)
- APT (1)
- Aqua ZeuS Gang (1)
- Armadillo Phone (2)
- Ashiyane Digital Security Team (5)
- ASProx (2)
- Astalavista (7)
- Astalavista Security Group (1)
- Astalavista.box.sk (4)
- ATM Skimmer (1)
- ATS (1)
- Australia (1)
- Authentication (2)
- Avalance Botnet (2)
- Avast (1)
- Background Check (1)
- BadB (1)
- Bahama Botnet (1)
- BakaSoftware (1)
- Bantu (1)
- BBC (1)
- Bebo (1)
- Bed Time Reading (1)
- Behrooz Kamalian (2)
- Best Practices (2)
- BGP (1)
- Big Brother (3)
- Bill Gates Botnet (1)
- Biography (1)
- Biometrics (1)
- Bitcoin (1)
- Bjorn Andreasson (1)
- Black Energy (1)
- Blackhat SEO (27)
- Blood and Honor (1)
- Blood and Honor Bulgaria (1)
- Boeing (1)
- Bogus Account (1)
- bother (1)
- Botners (1)
- Botnet (160)
- Botnets (21)
- Box.sk (1)
- Brian Krebs (1)
- Brute-Forcing (1)
- Bulgaria (18)
- Bulgaria Law Enforcement (14)
- Bulgarian Cyber Army (1)
- Bulgarian Cyber Army Hacking Group (1)
- Bullet Proof Hosting (1)
- Bust (1)
- C4I (2)
- CALEA (1)
- Caller ID (1)
- Caller ID Spoofer (1)
- Candid Wuest (1)
- CAPTCHA (2)
- Career Enrichment (1)
- Cash Transfers (1)
- CCTV (1)
- CDT (1)
- Cell Phone Monitoring (1)
- Cell Phone Surveillance (1)
- CellDEK (1)
- Censorship (28)
- Center for Democracy and Technology (1)
- CERT (1)
- Cheyenne Mountain Operations Center (1)
- China (9)
- China Eagle Union (1)
- CIA (15)
- CipherTrust (1)
- Classified Information (1)
- Client-Side Exploits (30)
- Client-Side Vulnerabilities (30)
- CNO (1)
- COCOM (1)
- Cold War (1)
- COMINT (1)
- Competitive Intelligence (3)
- Compliance (3)
- Computer Crime Survey (1)
- Computer Network Operation (1)
- Conficker (1)
- Confidential Connections (1)
- Conspiracy (1)
- Conspiracy Theory (1)
- Conti (8)
- Conti Ransomware (7)
- Conti Gang (8)
- Conti Ransomware (7)
- Conti Ransomware Gang (8)
- Cookies (1)
- CoolWebSearch (4)
- Corporate Risk Management (4)
- Counter Espionage (2)
- Counter Intelligence (1)
- Credit Cards (7)
- Crimeware (3)
- Critical Infrastructure (2)
- Crusade Affiliates (1)
- Crypters (1)
- Cryptography (6)
- Cryptome (2)
- Cryptoviral Extortion (2)
- CSIA (2)
- CVE (1)
- Cyber Attack (61)
- Cyber Espionage (73)
- Cyber Insurance (1)
- Cyber Jihad (34)
- Cyber Militia (7)
- Cyber Security Industry Alliance (1)
- Cyber Security Investment (9)
- Cyber Terrorism (40)
- Cyber Threat Actor Attribution Maltego Graphs (2)
- Cyber Warfare (68)
- Cyber Weapon (1)
- Cyber Weapons (1)
- CyberCamp 2016 (1)
- Cybercrime (334)
- Cybercrime Ecosystem (21)
- Cybercrime Forum (36)
- Cybercrime Forum Data Set (13)
- Cybercrime Incident Response (1)
- Cybercrime Incident Response Maltego Graphs (1)
- Cybercrime Search Engine (1)
- Cybercriminal (1)
- Cyberpunk (4)
- Cyberspace (22)
- Cybertronics (3)
- Daniel Brandt (1)
- Dark Vader (1)
- Dark Forum (1)
- Dark Web (10)
- Dark Web Onion (5)
- Dark Web Search Engine (2)
- DarkComet RAT (1)
- Darkode (1)
- Darkode Forum Community (1)
- Data Acquisition (1)
- Data Breach (10)
- Data Center (1)
- Data Leak (2)
- Data Mining (6)
- David Endler (2)
- DCLeaks (1)
- DDoS (10)
- DDoS For Hire (1)
- Defense Complex (1)
- Delicious Information Warfare (1)
- Denmark (1)
- Department of Defense (2)
- DHS (1)
- DIA (1)
- Digital Armaments (1)
- Digital Forensics (2)
- Digital Rights (8)
- Dilbert (1)
- Distributed Computing (4)
- Distributed Computing Project (4)
- Distributed Project (4)
- DNS (2)
- DNS Changer (1)
- DoD (3)
- DoJ (1)
- DotCom (1)
- DreamHost (1)
- Dropbox (1)
- Durzhavna Sigurnost (3)
- DVD of the Weekend (5)
- E-Banking (2)
- E-Business (3)
- E-Commerce (2)
- E-Shop (2)
- Eavesdropping (24)
- Ebay (1)
- ECHELON (2)
- ECOFIN Projects (1)
- Economics (3)
- eID (1)
- Electric Universe (1)
- Electromagnetic Pulse Weapons (3)
- Electronic Banking (1)
- ELINT (1)
- Emotet (2)
- Emotet Botnet (1)
- EMP (3)
- Encrochat (1)
- Encrochat Database Leak (1)
- Encrypted Communication (6)
- Encrypted Phone (1)
- Encryption (8)
- Enigma (2)
- ENISA (1)
- Enki Bilal (1)
- Enron (1)
- Erasmus Bridge (1)
- Eric Goldman (2)
- Espionage (6)
- Espionage Movie (2)
- Evgeniy Mikhaylovich Bogachev (1)
- Exmanoize (1)
- Exploit Broker (10)
- Exploit Kit (2)
- Exploits (39)
- Eyeball Series (1)
- F-Secure (1)
- Facebook (15)
- Fake Account (1)
- Fake Adobe Flash Player (4)
- Fake Certificate (1)
- Fake Chrome Extension (1)
- Fake Chrome Update (1)
- Fake Code Signing Certificate (1)
- Fake Confirmed Facebook Friend Request Email (1)
- Fake Documents (7)
- Fake Facebook Appeal (1)
- Fake Facebook Notification (1)
- Fake Facebook Profile Spy Application (1)
- Fake Firefox Update (1)
- Fake Hosting Provider (1)
- Fake ID (7)
- Fake Internet Explorer Update (1)
- Fake Passport (8)
- Fake Personal ID (1)
- Fake Safari Update (1)
- Fake Security Software (48)
- Fake Tech Support Scam (1)
- Fake Utility Bill (4)
- Fake Video Codec (2)
- Fake Visa (1)
- Fake Visa Application (1)
- Fake Web Site (1)
- Fake Who's Viewed Your Facebook Profile Extension (4)
- Fake YouTube Player (1)
- Fast-Flux (3)
- FBI (4)
- FBI Most Wanted (5)
- FCC (1)
- FDIC (1)
- Financial Management (1)
- Firas Nur Al Din Dardar (1)
- FireEye (1)
- Flashpoint Intel (1)
- Foreign Influence Operations (2)
- Forensics (2)
- Forwarderz (2)
- FoxNews (1)
- Fraud (17)
- Free Speech (17)
- FSB (2)
- FTLog (1)
- FTLog Worm (1)
- Gartner (1)
- Gavril Danilkin (1)
- GazTranzitStroyInfo (1)
- GCHQ (8)
- GDBOP (1)
- Generation I (1)
- George Bush (1)
- Georgi Markov (1)
- Georgia (4)
- Germany (1)
- Gift Cards (1)
- GiveMeDB (1)
- Global Security Challenge (1)
- Goa Trance (1)
- GoDaddy (1)
- Google (11)
- Google Firebase (1)
- Google Ads (1)
- Google Docs (6)
- Google Earth (4)
- Google Groups (1)
- Google Hacking (2)
- Google Maps (3)
- Google Play (1)
- Google Store (1)
- Greece (1)
- Growth Hacker (2)
- GRU (1)
- Guccifer 2.0 (1)
- GUI (1)
- Gumblar (1)
- Hacked Database (5)
- Hacked Web Site (5)
- Hacker (2)
- Hackers (2)
- Hacking (233)
- Hacking Book (1)
- Hacking Forum (1)
- Hacking Group (5)
- Hacking Groups (1)
- Hacking Tools (1)
- HackPhreak (1)
- HackPhreak Hacking Group (1)
- Hacktivism (5)
- Haiti (1)
- Hamas (1)
- Hezbollah (1)
- High Tech Brazil Hack Team (1)
- Hilary Kneber (4)
- HKLeaks (1)
- Home Molestation (8)
- Homebrew (1)
- Honeynet Project (1)
- Honker Union of China (1)
- HUMINT (2)
- ICBM (1)
- ID Theft (4)
- iDefense (3)
- Identity Theft (4)
- Illegal Arrest (13)
- Illegal Hosting (1)
- Illegal Restraint (3)
- IMINT (2)
- IMLogic (3)
- India (1)
- India Company (1)
- Indicator of Compromise (1)
- Information Operations (2)
- Information Security (598)
- Information Security Forum (1)
- Information Security Market (5)
- Information Warfare (67)
- Infrastructure Security (1)
- InFraud (1)
- InFraud Cybercrime Gang (1)
- InFraud Cybercrime Syndicate (1)
- InFraud Organization (1)
- InqTana Mac OS X Malware (1)
- Insider (8)
- Insider Monitoring (2)
- Insider Threat (9)
- Instant Messaging (6)
- Intellectual Property (1)
- Intelligence (19)
- Intelligence Agency (17)
- Intelligence Community (35)
- Internal Revenue Service (1)
- International Exploit Shop (2)
- Internet (15)
- Internet Censorship (23)
- Internet Economy (4)
- Internet Relay Chat (1)
- Investment Banking (6)
- IoC (1)
- IP Cloaking (2)
- IP Hiding (1)
- IP Spoofing (1)
- iPowerWeb (1)
- IPSec (1)
- IPv4 (1)
- IPv6 (2)
- Iran (19)
- Iran Election (1)
- Iran Election 2009 (1)
- Iran Hacker Groups (7)
- Iran Hacking Groups (7)
- Iran Mabna Hackers (1)
- IRC (1)
- IRS (1)
- ISIS (1)
- Israel (1)
- Jabber (5)
- JabberZeuS (2)
- Javor Kolev (1)
- Jeffrey Carr (1)
- Joanna Rutkowska (1)
- Johannes Ullrich (2)
- John Young (1)
- K Rudolph (1)
- Kaseya (1)
- Kaseya Ransomware Attack (1)
- Katrina (1)
- Keylogger (1)
- KGB (7)
- Kidnapping (14)
- Koobface (29)
- Koobface Botnet (3)
- Korean Demilitarized Zone (1)
- KrotReal (1)
- Latest News Articles (2)
- Latvia (1)
- Law Enforcement (29)
- Lawful Interception (5)
- Leaks (1)
- Lenovo (3)
- Liberty Front Press Network (1)
- Lizamoon (2)
- Loads.cc (1)
- Localization (1)
- Location Tracking (2)
- Lockheed Martin (1)
- Logicube (1)
- Lone Gunmen (3)
- Lovely Horse (2)
- Lubyanka Square Headquarters (1)
- M4 Project (1)
- Mac OS X (3)
- Malicious Software (190)
- Maltego (6)
- Maltego Graphs (1)
- Malvertising (4)
- Malware (49)
- Malware Information Sharing Platform (1)
- Marketing (2)
- Mass Web Site Defacement (10)
- Mastercard (1)
- McAfee (3)
- MD5 (1)
- Media Methane (1)
- Memoir (2)
- Metrics (1)
- Microsoft (3)
- Microsoft Live (1)
- Military Communications (2)
- Ministry of Interior (1)
- MISP (1)
- Missile Base (1)
- Mobile (5)
- Mobile Application (2)
- Mobile Communication Censorship (1)
- Mobile Internet (3)
- Mobile Location Tracking (5)
- Mobile Malware (10)
- Mobile Security (2)
- Mohammad Sagegh Ahmadzadegan (1)
- Money Laundering (24)
- Money Mule (26)
- Money Mule Recruitment (26)
- Monoculture (1)
- Morgan Stanley (1)
- Moses Staff (1)
- Most Wanted Cybercriminals (1)
- MSN (3)
- MSRC (1)
- MSRC Researcher Recognition Program (1)
- Muhammad Cartoons (1)
- MVR (1)
- MyWebFace (1)
- NASA (1)
- National Cyber Security Centre (1)
- National Security (2)
- Native Intelligence (1)
- NBC (2)
- NCSC (1)
- NetAssist LLC (1)
- NetCraft (1)
- Network Centric Warfare (1)
- Network Solutions (3)
- New Media (9)
- Nikolay Nedyalkov (1)
- Nikopol Trilogy (1)
- Nintendo (1)
- Nintendo DS (1)
- NordVPN (1)
- Norman Sandbox (1)
- North Korea (3)
- North Korea Missile Launch Pad (1)
- NSA (16)
- NSO Group (1)
- NSO Group Spyware (1)
- Nuclear Weapons (3)
- Nyxem (1)
- OEM (1)
- Offensive Cyber Warfare (1)
- OMEMO (1)
- Omerta (1)
- One-Time Password (1)
- One-Time Passwords In Everything (2)
- OneCare (1)
- Online Advertising (5)
- Online Fraud (12)
- Online Marketing (3)
- Online Propaganda Campaign (1)
- Online Scam (3)
- Open Source Malware (3)
- Operation EQUALIZER (1)
- Operation Uncle George (8)
- OPIE (1)
- OPSEC (1)
- Osama Bin Laden (1)
- OSINT (118)
- OSINT Training (1)
- OTC (1)
- OTP (1)
- Over-The-Counter (1)
- Packers (1)
- Parked Domains (1)
- Passwords (2)
- Pavlin Georgiev (1)
- Pay Per Install (3)
- PayPal (1)
- Perplex City (1)
- Persistent Cookies (1)
- Personal Career (1)
- Personal Data (4)
- Pharmaceutical Scams (1)
- Phileas Crawler (1)
- Phishing (12)
- Phishing Campaign (8)
- Phishing Domain Farm (1)
- Phishing Toolbar (2)
- PhishTube (1)
- Phreedom (1)
- Physical Security (1)
- Pinterest (1)
- Piracy (1)
- PlushForums (1)
- Podcast (2)
- Point of Sale Terrminal (1)
- Politics (1)
- PornTube (1)
- POS (1)
- Potentially Unwanted Application (2)
- PR (1)
- Press Coverage (1)
- Privacy (34)
- Project RAHAB (1)
- Prolexic (1)
- Protonmail (4)
- Proxy Service (1)
- Psychedelic Trance (2)
- PSYOPS (2)
- Psytrance (2)
- Psytrance Song of the Day (2)
- Qassam Cyber Fighters (2)
- Radicati Group (1)
- Ransomware (20)
- RAT (1)
- Ray Kurzweil (1)
- RBN (1)
- Reconnaissance Satellite (2)
- Red Joan (1)
- Regulation (1)
- Remote Access Tool (4)
- Reporters Without Borders (1)
- Return On Investment (9)
- Return On Security Investment (10)
- REvil Ransomware Group (1)
- Revolution in Militvry Affairs (1)
- RIPA (1)
- Risk Management (2)
- Rogue Account (1)
- Rogue Chrome Extension (1)
- Rogue Facebook Appeal (1)
- Rogue Security Software (2)
- Rogue Video Codec (1)
- Rogue YouTube Player (1)
- Rogueware (3)
- ROI (3)
- Roman Polesek (1)
- Root Server (2)
- Rootkit (1)
- ROSI (7)
- RSA (1)
- RSA Conference (1)
- Russia (12)
- Russia Small Group (1)
- Russian (1)
- Russian Bomber (1)
- Russian Business Network (4)
- Russian Submarine (1)
- Safe Harbor (1)
- Satellite Imagery (3)
- Satellite Jamming (1)
- Satellite SIGINT (1)
- Scam (4)
- Scams (9)
- Scandoo (1)
- ScanSafe (1)
- Scareware (50)
- Scientific Intelligence (1)
- Scribd (1)
- Search Engine (16)
- Search Engine Optimization (26)
- SEC (1)
- SecondEye Solutions (2)
- Secret Service (1)
- Secure Communication (1)
- SecureDrop (1)
- Securities and Exchange Commission (1)
- Security (645)
- Security Awareness (2)
- Security Book (1)
- Security Breach (4)
- Security Conference (2)
- Security Directory (1)
- Security Education (1)
- Security Event (2)
- Security Forum (1)
- Security Game (1)
- Security Industry (6)
- Security Interviews (3)
- Security Investment (5)
- Security Metrics (3)
- Security Podcast (2)
- Security Project (1)
- Security Research (1)
- Security Statistics (3)
- Security Training (1)
- Security Trends (8)
- Sensitive Information (2)
- SEO (2)
- Shadow Server (1)
- ShadowCrew (5)
- SIGINT (2)
- Silent Circle (1)
- Sipco Systems (1)
- SIPRNET (2)
- SITE Institute (1)
- SiteAdvisor (4)
- Skype (2)
- Sniffing (1)
- Social Engineering (4)
- Social Network Analysis (5)
- SocialMediaSystem (1)
- Software Piracy (1)
- Solarwinds (1)
- Song of the Day (2)
- Sophos (1)
- Soviet Union (1)
- Space Warfare (3)
- Space Weapons (1)
- Spam (10)
- Spam Campaign (7)
- Spam Operations (7)
- Spear Phishing (2)
- Spoofing (1)
- Sprott Asset Management (1)
- Spyware (3)
- SQL Injection (3)
- SSL (2)
- SSN (1)
- Stalkware (1)
- Starlight (1)
- Stealth Ideas Inc (1)
- Steganography (1)
- STIX (3)
- STIX2 (3)
- Stolen Credit Card (9)
- Stolen Credit Cards (5)
- Stolen Gift Cards (1)
- Strider Crawler (1)
- Sub7 (1)
- Suri Pluma (1)
- Surveillance (24)
- Swine Flu (1)
- Symantec (5)
- Symbian (1)
- Syria (2)
- Syrian Electronic Army (1)
- Syrian Embassy (1)
- Taia Global (1)
- TAN (1)
- TAXII (3)
- TDoS (1)
- Team Code Zero (1)
- Team Code Zero Hacking Group (1)
- Tech Support Scam (1)
- Technical Collection (73)
- Technical Mujahid (1)
- Telephony Denial of Service Attack (1)
- Terrorism (8)
- th3j35t3r (1)
- THAAD (1)
- The Bunker (1)
- The Immortals (1)
- The Lawnmower Man (2)
- The Outer Limits (4)
- Thought Leadership (1)
- Thousand Talents Program (1)
- Threat Intelligence (18)
- Threat Intelligence Feed (2)
- Threat Intelligence Report (1)
- TIA (4)
- Tipping Point (1)
- Top Secret Program (1)
- Tor (1)
- Tor Project (1)
- Torrent (1)
- TorrentReactor (1)
- Total Information Awareness (4)
- Travel Without Moving (9)
- TrendMicro (2)
- Trickbot (1)
- Trickbot Gang (1)
- Trickbot Malware (1)
- Trickbot Malware Gang (1)
- Trifinite Group (1)
- Trojan Horse (2)
- TROYAK-AS (2)
- Tutanota (2)
- Twitter (4)
- Two Factor Authentication (1)
- Two-Factor Authentication (3)
- Typosquatting (3)
- U.K National Cyber Security Centre (1)
- U.S Bureau of Engraving and Printing (2)
- U.S Cyber Command (1)
- U.S Driving License (1)
- U.S Elections (3)
- U.S Sanctions (1)
- U.S Secret Service (1)
- Underground Search Engine (1)
- United Kingdom (4)
- University ID Card (1)
- Vasil Moev Gachevski (1)
- Vault 7 (1)
- VeriSign (1)
- Vertex Net Loader (1)
- Virtual Private Network (2)
- Virtual Reality (5)
- Virtual Reality Social Network (4)
- Virtual World (4)
- Virus (1)
- Virus for You (1)
- Virus Map (1)
- Virus Recovery Button (1)
- Viruses (2)
- VirusTotal (1)
- Visa (1)
- Visual Information System (2)
- Visualization (3)
- Void Balaur Malware Gang (1)
- VoIP (2)
- VPN (3)
- Vulnerabilities (39)
- Vulnerability Broker (10)
- War Driving (1)
- War Games (1)
- Weapon Systems (1)
- Web 2.0 (3)
- Web Application Worm (1)
- Web Crawler (2)
- Web Inject (1)
- Web Proxy Service (1)
- Web Shells (1)
- Web Site Defacement (10)
- Web Site Defacement Groups (4)
- Webroot (2)
- WHGDG (1)
- WhoisXML API (10)
- WhoisXML API Jabber ZeuS Gang (1)
- Wireless (2)
- Wireless Hacking (1)
- Wireless Internet (2)
- Wiretapping (10)
- WMF Vulnerability (2)
- World Hacker Global Domination Group (1)
- X-Files (2)
- X-Tunnel (1)
- XMPP (4)
- XSS (1)
- Yahoo (2)
- Yaroslav Vasinskyi (1)
- Yavor Kolev (1)
- YouTube (1)
- ZDNet (1)
- ZDNet Zero Day Blog (1)
- Zero Day Exploit (6)
- Zero Day Initiative (2)
- Zerodium (1)
- ZeuS (4)
- Zombie Alert (2)
- Zone-H (2)
- Zotob (1)
Dancho Danchev's Blog - Mind Streams of Information Security Knowledge is wearing HalfBaked. Free WP-Theme by GuyFisher. Converted to Blogger by Template-Godown.
